NIS-2 services
Achieve NIS-2 compliance to mitigate cybersecurity risks and minimise business disruption.What is NIS-2?
NIS-2 is an update of the European Union’s Network and Information Security (NIS) Directive to enhance cybersecurity and resilience across organisations in the EU. The NIS-2 Directive came into effect in January 2023, with the official deadline for transposition into national law set for 17 October 2024, when the requirements will become applicable in all countries that have adopted the national implementation. Organisations across the EU must meet the cybersecurity requirements by this date to ensure compliance.
TÜV SÜD’s NIS-2 services ensure you have a trusted partner with the expertise, resources, and global presence to help protect your organisation from cybersecurity threats while effectively meeting regulatory requirements.
Why NIS-2 compliance is important
NIS-2 compliance is crucial for organisations active within the European Union (EU). By adhering to NIS-2, businesses can effectively identify and mitigate cybersecurity risks, reducing the chances of operational disruptions caused by cyber incidents and avoiding significant fines or reputational damage.
Customers and clients are increasingly aware of cybersecurity vulnerabilities that can affect network and information systems along their entire supply chain. Achieving NIS-2 compliance not only builds trust and confidence but also provides a competitive edge, reassuring them that their data and information are secure when partnering with your organisation.
TÜV SÜD’s NIS-2 services not only safeguard your business against cyber threats, they also position you as a reliable and secure partner, enhancing your reputation and fostering long-term growth and sustainability. With our support, you ensure continuous protection and compliance, allowing your business to adapt to evolving cyber threats while maintaining a strong market position.
How TÜV SÜD’s NIS-2 services can help you with compliance
TÜV SÜD is a globally recognised leader in testing, inspection, and certification services. We have extensive experience in cybersecurity and regulatory compliance, working with more than 10,000 customers globally. With a presence in over 1,000 locations, our experts can support your organisation's NIS-2 compliance needs across multiple jurisdictions and markets.
To ensure full compliance, our comprehensive NIS-2 services offer end-to-end support tailored to meet NIS-2 requirements. This includes a thorough NIS-2 Risk Assessment, gap analysis, audits, and implementation assistance. Our client-centric approach focuses on understanding your unique business needs, allowing us to tailor our services to deliver practical, effective solutions.
TÜV SÜD is renowned worldwide as an independent and impartial advisor and auditor. Global acceptance of our validations is the result of our commitment to rigorous quality standards, ensuring thorough and reliable NIS-2 risk assessments that meet regulatory requirements and industry best practices.
Our NIS-2 Services: What We Offer
A well-executed cybersecurity strategy ensures you achieve and maintain NIS-2 compliance for your network and information systems. Our NIS-2 services are designed to help you build a resilient programme that not only addresses current cyber threats but also adapts to evolving risks and aligns with your digital business strategies. We don’t just focus on assessing and implementing the present state of your cybersecurity posture; we also prepare your organisation for your future vision and growth.
TÜV SÜD’s experts provide clear insights into your cyber risk posture and capabilities, enabling you to make informed investment decisions. We assist in implementing a strategic cybersecurity programme that incorporates structured decision-making. With social engineering being a common tactic in cyberattacks, we enhance your risk awareness through targeted staff education and training to minimise human error.
Our approach consists of:
• Preparation
• Scoping
• Risk assessment
• Documentation review
• Interviews and observations
• Gap analysis
• Reporting
Frequently asked questions (FAQs)
What are the NIS-2 categories?
The categorisation of entities as essential or important can vary by member state, but generally, the following sectors are included:
Essential sectors:
• Energy
• Transport
• Banking
• Financial market infrastructures
• Health
• Drinking water and wastewater
• Digital infrastructure, including internet exchange points, DNS, and cloud computing services
Important sectors:
• Digital providers, including online marketplaces, online search engines, and social networking services platforms
• Public administration
• Space
• Postal and courier services
• Waste management
• Industrial manufacturing
• Manufacturing and distribution of chemicals
• Food production processing and distribution
• Research
What is the transition timeline for NIS-2?
- 7 June 2016 the Network and Information Security (NIS) Directive is adopted.
- 5 September 2018 member states transpose NIS into national law.
- 7 July 2020 European Commission starts consulting on NIS reform.
- 16 December 2020 The European Commission publishes a proposal for NIS-2.
- 13 May 2022 European Parliament votes to adopt NIS-2.
- 10 November 2022 The Council of the EU approves NIS-2.
- 28 November 2022 NIS-2 is published in the Official Journal.
- 16 January 2023 NIS-2 enters into force.
- 17 October 2024 member states transpose NIS-2 into national law.
- From 17 October 2024 onwards the NIS-2 Directive becomes enforceable. Organisations across the EU must meet the cybersecurity requirements by this date to ensure compliance.
Am I affected by NIS-2? What are the thresholds?
Companies must determine themselves whether they fall within the scope of NIS2. TÜV SÜD can shelp you to determine if you are affected. In most EU member states the national cybersecurity authorities, such as Germany's Federal Office for Information Protection (BSI), offerguidance. in determining whether your organization is likely to be affected (NIS-2 Applicability Check in German).
The following criteria are decisive for this:
-
The size of the company: If companies have more than 50 employees and generate more than 10 million euros in revenue per year, they are affected by NIS-2 if they operate in a relevant sector.
-
The sector: NIS-2 defines 18 affected sectors that are considered as either essential or important and will have to abide by the same baseline cybersecurity requirements, with stricter requirements for essential entities in the most critical sectors.
Some organisations are also affected regardless of their size. This applies, for example, if systemic risks exist in the event of a failure.
Is there a certification for NIS-2?
Companies that are likely to be impacted by NIS-2 should begin with implementing an Information Security Management System (ISMS) in accordance with ISO 27001, which provides organisations with a clear framework to systematically and continuously assess and improve their processes and IT systems for vulnerabilities. With an ISMS, companies can reduce their cyber-attack surface and ensure consistent business continuity.
Ideally, affected companies should contact their auditors as soon as possible to discuss the approach and avoid last-minute pressure.